Description
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINDEVSERVER-590124
Related Vulnerabilities
CVE-2021-32854 Vulnerability in npm package textangular
CVE-2017-16138 Vulnerability in maven package org.webjars.npm:mime
CVE-2023-0842 Vulnerability in npm package xml2js
CVE-2019-10758 Vulnerability in npm package mongo-express
CVE-2022-45143 Vulnerability in maven package org.apache.tomcat:tomcat-catalina